2023-05-19, 16:45–17:15, Ville-Marie
We've often had the opportunity to hear about bug hunting & bug bounty programs from the researcher perspective, or in the form of sales pitches from companies that help build them, but less often do we hear from the folks who work on those programs as their main focus.
In this talk we'll explore the ins and outs of GitHub's Bug Bounty program, along with advice for those working in or building BB/VDP programs, or submitting bounty reports. GitHub was an early adopter of bug bounties, with our program dating back to January 2014. Since then, the program has been recognized as a leading bug bounty program consistently offering generous awards with clear scoping. In addition to having a dedicated team to work with researchers, we’ve paid out over $3,500,000 USD in bounties to date.
- GitHub's Bug Bounty program, including payouts and key milestones
- How GitHub handles report triage & severity assignment
- How GitHub’s bounty team interacts with researchers and aims to more deeply understand and analyze reports
- Operational considerations of working with both a SaaS & on-prem product
- Report/vulnerability disclosure
- Bug bounty triage as a job & career stepping stone
- Tips for researchers and bounty staff
Attendees will walk away having a better understanding of how GitHub's Bug Bounty team and program has grown over the past 8 years, the nuances and challenges that triagers/engineers face working with bounty reports, and also how to improve their ROI when working on/with programs.
Logan has been a cybersecurity enthusiast since getting online in the 90s and currently focuses on helping grow GitHub’s Bug Bounty program. During his free time, Logan dabbles in powerlifting, CTFs, and retro gaming.